Free BYOD policy templates for small business: full policy, short version, signed wipe consent form, device return procedure, security and stipend. DOCX.
Six free bring your own device policy templates for small business, built around the parts generic examples skip: what the company may and may not touch on a personal phone, a separately signed remote wipe consent, state cell phone reimbursement rules, the overtime risk of after-hours email, and a device return procedure for termination. Download as DOCX.
A BYOD policy is the written agreement that lets an employee use a personal phone, tablet, or laptop for work, and sets out exactly what the company may do to that device in return. It answers the four questions that actually matter: what the company can see, what it can erase, who pays for the plan, and what happens on the last day.
The first time this became real for me was a resignation on a Friday afternoon. A salesperson had every customer number in the contacts app on a phone the company had never paid a cent toward, and nobody could tell me whether we were allowed to touch it. We were not, because nothing had ever been signed. That gap is the whole reason this page exists.
Below are six templates: a full policy, a one-page statement, a signed consent and acknowledgment form, an internal device return and wipe procedure, a security standard, and a stipend addendum. Each downloads as a Word document, free and without an email. They slot into the broader HR policy manual alongside your acceptable use policy.
TL;DR
A BYOD policy sets the terms for personal device use at work: security minimums, what the company may and may not access, reimbursement, hours of work, and removal of company data. It works only alongside a consent form signed before access is granted, with remote wipe consent separate. Several states require paying a reasonable share of the phone bill.
What a BYOD Policy Is
A BYOD policy is a written set of terms under which employees may use personal devices to access company email, files, and systems. Bring your own device is the full phrase behind the abbreviation. The policy defines enrollment, security requirements, access boundaries, payment for work use, hours-of-work rules, and how company data is removed when the arrangement ends.
It is not one document, and that is where most small companies come up short. The policy states the rules. A signed consent form, collected before any access is granted, is what records the employee agreed to them. An internal removal procedure is what makes the last day routine instead of improvised. Publishing the first without the second two is the most common failure I see.
Professional templates for the policy itself are widely available, including a customizable version from SHRM. What the generic versions tend to leave thin is the employer-side detail that carries real cost: the wipe consent language, the state reimbursement question, and the overtime exposure created by a phone that never stops buzzing.
What a Company May and May Not Do to a Personal Phone
The company may control company data, company accounts, and the security posture of the device. It may not go rummaging through personal content. That line is simple to state and easy to cross once a management tool is installed, which is why the policy has to name both sides of it in writing.
What the company may do
Require a passcode, encryption, and a current operating system before granting access
Enroll the device in a management tool and check that it stays compliant
Read and retain company email, company files, and company chat on the device
Log sign-ins to company systems, including time and IP address
Remove company data, including by remote wipe, under a signed consent
Withdraw access at any time and require a company-owned device instead
What it should not do
Browse personal photos, personal messages, or a personal email account
Track location outside working hours absent a legal requirement or hold
Read personal browsing history on a network the company does not control
Wipe personal content without consent, or when a selective wipe would do
Skip a state-required written notice before monitoring begins
Require a personal device without addressing reimbursement where state law applies
The technical mechanism that keeps you on the right side of that line is separation. Modern device management can create a work profile or a managed application container: company email, files, and chat live inside it, personal content lives outside it, and the company only ever manages the container. Set that up and most of the privacy argument disappears before it starts.
The second mechanism is notice. Several states require written notice before an employer monitors employee electronic activity, and the rules differ enough that you should check the ones where your people actually work. Our guide to employee monitoring laws covers the notice question in more detail, and a standalone monitoring consent form handles the signature.
Say What You Will Not Look At
Most BYOD policies list what the company can access and stop there. Adding an explicit list of what the company will not access, personal photos, personal messages, personal email, personal browsing, does two useful things: it makes people willing to enroll, and it gives you a written standard to point to if anyone later claims you overreached. It costs you nothing you actually wanted. This is general information, not legal advice.
Remote Wipe and Written Consent
You can remotely wipe a personal device, but only with written consent obtained before access was granted, and you should almost always remove company data rather than everything. A selective wipe deletes the work profile and company applications. A full factory reset erases the employee personal life along with it.
Treat the selective wipe as the default and the full reset as an exception you have to justify. In the policy, name both, define when each applies, and require a named person to authorize a full reset with a written reason for why a selective wipe was not possible. That single paragraph is the difference between an administrative step and an argument.
1
Get consent in writing before access, not after
The consent form goes out with the offer or at enrollment, and company access is granted only once it comes back signed. Consent collected after an incident is worth very little.
2
Initial the wipe section separately
Put the remote wipe terms in their own section with a separate initial line. It removes any argument that the employee never noticed what they were agreeing to.
3
Spell out selective versus full
State plainly that a selective wipe removes only company data, that a full reset erases everything, and that the full reset is reserved for a lost, stolen, or compromised device where separation is not possible.
4
Put backup responsibility on the employee
The form should say the employee is responsible for backing up personal content and releases the company for personal data lost in a wipe performed under the policy.
5
Build the separation technically
A work profile or managed container makes the selective wipe possible in the first place. Without it, your only removal option is the one most likely to end in a dispute.
How much does an unsigned consent cost? In one Texas case, a former employee sued after his personal phone was remotely wiped following his exit. The federal court threw out his Stored Communications Act claim because data on a personal device is not in electronic storage as that statute uses the term, and threw out his computer-fraud claim on the separate ground that his claimed loss did not meet the statutory threshold. The employer won both federal claims and still spent more than a year in litigation, and the state law claims went out without prejudice. The fix for all of it is a signature that takes ninety seconds to collect.
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
It depends on the state, and in a handful of states the answer is clearly the employer. There is no general federal statute requiring reimbursement of a personal phone bill, but several states require employers to reimburse necessary business expenses, and requiring work use of a personal phone lands squarely inside that.
California is the strictest. Labor Code section 2802 requires an employer to indemnify an employee for all necessary expenditures or losses incurred in direct consequence of the discharge of their duties (California Legislative Information). A California appellate decision applied that to phones and held the reimbursement owed is a reasonable percentage of the bill whether the plan has unlimited or limited minutes, and that it does not matter whether a third person pays the bill at all.
Rule
What it requires
What it means for BYOD
California Labor Code 2802
Indemnify employees for all necessary expenditures or losses incurred in direct consequence of their duties
Pay a reasonable percentage of the personal phone bill where work use is required, even on an unlimited plan and even if someone else pays it
Illinois Wage Payment and Collection Act, section 9.5
Reimburse necessary expenditures within the scope of employment that primarily benefit the employer
A stipend or documented reimbursement; employees submit within 30 calendar days unless a written expense policy allows longer
Other states with expense reimbursement laws
Wording, triggers, and defenses differ, and some jurisdictions limit the duty to narrow categories such as tools and uniforms
Check the rule for every state where an employee actually works, not just where the office sits
Federal FLSA, free and clear rule
Wages must be paid free and clear; an expense primarily for the employer cannot be shifted to the employee
An unreimbursed phone cost cannot cut a non-exempt employee below minimum wage or reduce overtime pay in any workweek
States with no reimbursement statute
No general obligation to reimburse
A stipend is optional, but it still documents that the phone is used for work and keeps the arrangement from feeling like a tax on the employee
The federal floor applies everywhere. Under the wage regulations, wages must reach the employee free and clear, and requiring an employee to bear a cost that primarily benefits the employer violates the law in any week the cost cuts into minimum wage or overtime (29 CFR 531.35). For a minimum-wage hourly worker required to carry a work phone, that ceiling arrives faster than people expect.
The practical answer for a small business is a flat monthly stipend, set at an amount you can defend as a reasonable share of a normal plan, with a written path for an employee to ask for a review. Route it through your expense reimbursement policy so the accountable-plan treatment and the documentation are handled the same way as every other expense.
The After-Hours Overtime Risk
A personal phone in a non-exempt employee pocket is a wage-and-hour exposure, not just a security one. Time spent reading and answering work messages after a shift is time worked, it has to be recorded, and it has to be paid, including overtime if the week goes over the threshold.
Suffered or Permitted Is the Standard
Under the FLSA, to employ means to suffer or permit to work, and work not requested but suffered or permitted to be performed is work time that must be paid for by the employer. The reason is immaterial (U.S. Department of Labor, Fact Sheet #22). The hours-worked regulations carry the same rule to work done away from the workplace: under 29 CFR 785.12, if the employer knows or has reason to believe the work is being performed, it must count that time as hours worked.
Read that standard against how a small team actually operates. A manager sends a question at 9 p.m. because it is on their mind. The hourly employee answers in four minutes because their phone is right there and they want to look reliable. Nobody logged anything, and the company now has unpaid work time it knew about, because the manager watched the reply arrive.
Three controls handle it. Put an hours-of-work section in the BYOD policy that requires advance approval before working outside scheduled hours. State that unapproved time will still be reported and paid, and that any correction is a performance conversation rather than a deduction. Then train managers not to send messages that imply an immediate reply from an hourly employee. If you are unsure who this applies to, start with exempt versus non-exempt classification, because the rule only reaches the non-exempt side.
Security Minimums Worth Enforcing
Set a short list of requirements you can actually check automatically, and enforce them through a management tool rather than trusting a signature. A passcode, a short auto-lock timeout, encryption, a supported operating system version, and multi-factor authentication on company accounts cover most of the realistic risk for a small business.
On the device
Passcode or biometric plus a short auto-lock timeout
Encryption on, which is the default on current phones
An operating system version still receiving security updates
No jailbreak or root, checked by the management tool
On the accounts
Multi-factor authentication on every company account
Company data stays inside company applications
No company email forwarded to a personal address
No customer data pasted into unapproved third-party tools
On the network
Company VPN on any network the employee does not control
No company access from shared or public computers
Home router on current firmware with a changed password
When something goes wrong
Lost or stolen device reported within a set window
Phishing clicks reported without fear of punishment
Access cut first, wipe second
Every incident written down and filed
Keep the list short on purpose. A twenty-item standard that nobody enforces is worse than a six-item one that your device management tool checks on every connection, because the long version creates a written expectation you are visibly failing to meet. The data-handling rules matter as much as the device settings, and they overlap with your email policy and your employee data protection policy.
One more thing belongs in the standard: a reporting window with an explicit no-punishment line. People hide a lost phone or a clicked phishing link for a day out of embarrassment, and that day is where the actual damage happens. Say plainly that reporting fast is never punished and that concealing an incident is the violation.
Which Template Should You Use?
Take the full policy plus the consent form as the minimum viable set, because the policy without the signature does very little. Add the wipe procedure before your next departure, the security standard if you use a device management tool, and the stipend addendum if anyone works in a state that requires expense reimbursement.
BYOD Policy (Full)
The flagship
The complete policy: eligibility and enrollment, what the company can and cannot access, security requirements, reimbursement, hours of work for non-exempt employees, remote wipe, a monitoring notice, and separation. The version to adapt if you only take one.
Short BYOD Policy Statement
One page
A concise version for a small team or an employee handbook section. Seven numbered commitments, the non-exempt hours rule, the access boundary, and the stipend line. Grow into the full policy when regulated data or headcount makes it worth it.
Consent and Acknowledgment Form
Sign before access
The signed form that makes the rest defensible: device details, policy acknowledgment, consent to device management, a separately initialed remote wipe consent, the non-exempt hours acknowledgment, and the reimbursement election.
Device Return and Wipe Procedure
The internal runbook
The step-by-step for removing company data: check for a legal hold, cut access first, choose the narrowest wipe, handle in-person removal, settle the phone number, and record what you did. Includes what to do if a departing employee refuses.
Mobile Device Security Standard
The technical minimums
A companion standard listing the requirements you actually enforce: screen lock, auto-lock timeout, encryption, supported operating system, multi-factor authentication, data handling, network rules, and incident reporting windows.
Stipend and Reimbursement Addendum
The money part
Four ways to pay for work use of a personal phone: a flat stipend, a percentage of the actual bill, itemized reimbursement, or a company-owned device. Includes a state-specific section and a process for an employee to ask for a review.
Start With Two Documents, Not Six
If you only have an hour, adopt the full policy and the consent and acknowledgment form, and stop granting company access to any device that has not returned a signed form. Add the device return and wipe procedure before your next exit, the security standard when you roll out device management, and the stipend addendum as soon as someone works in a necessary-expense state. Then have US counsel review the set.
6 Free BYOD Policy Templates
Download all six as a single Word document, or copy them individually. Fill in the bracketed values for passcode length, lock timeout, reporting window, stipend amount, and the states where your employees work, then have US employment counsel review before you adopt anything.
Download All 6 BYOD Policy Templates
A full BYOD policy, a one-page statement, a signed consent and acknowledgment form, a device return and wipe procedure, a mobile device security standard, and a stipend and reimbursement addendum. All in one DOCX.
Template 1: BYOD Policy (Full)
The complete policy: eligibility and enrollment, what the company can and cannot access, security requirements, reimbursement options, an hours-of-work section for non-exempt employees, remote wipe terms, a monitoring notice, and separation. This is the one to adapt if you take only a single document.
BYOD Policy (Full)
BRING YOUR OWN DEVICE (BYOD) POLICY
[Company Name]
Effective date: _ Policy owner: __
Last reviewed: _
1. PURPOSE AND SCOPE
This policy explains the terms under which employees of [Company Name] may use a
personal device (phone, tablet, or laptop) to access company systems, email, files,
and customer information. It applies to every employee, contractor, and temporary
worker the company approves for personal-device access, and to every personal device
used for that purpose.
Participation in BYOD is voluntary. An employee who does not want to enroll a personal
device may request a company-owned device instead, and [Company Name] will provide one
where the role requires it. No employee is required to buy a device.
2. ELIGIBILITY AND ENROLLMENT
To use a personal device for work, an employee must:
•Request approval from [manager / IT / HR] and identify the device by make, model,
and operating system version.
•Sign the BYOD Consent and Acknowledgment Form before access is granted.
•Enroll the device in the company's mobile device management (MDM) or mobile
application management tool, if the company uses one.
•Keep the device on a supported operating system version that still receives
security updates.
Access is granted per device. Adding a second personal device requires a new request.
Approval may be withdrawn at any time.
3. WHAT THE COMPANY CAN AND CANNOT ACCESS
The company can access, monitor, and manage:
•Company email, calendar, contacts, files, and applications on the device.
•The company work profile or managed application container, where one is used.
•Device-level security settings the company requires (passcode, encryption, screen
lock timeout, operating system version).
•Records of connections to company systems, including sign-in times and IP addresses.
The company does not seek access to, and will not intentionally review:
•Personal photos, videos, music, or documents stored outside company applications.
•Personal email, personal messaging apps, or social media accounts.
•Personal contacts, personal call logs, or personal browsing history on personal
networks.
•Location data outside working hours, except where required by law or a legal hold.
If a legal hold, litigation, investigation, or regulatory request requires broader
access to a personal device, the company will notify the employee where permitted and
will limit the scope to what is required.
4. SECURITY REQUIREMENTS
Every enrolled device must have:
•A passcode, PIN, or biometric lock of at least [6] characters or equivalent.
•Automatic screen lock after no more than [5] minutes of inactivity.
•Device encryption enabled (on by default on current phones).
•Current operating system and application security updates.
•Multi-factor authentication on every company account accessed from the device.
Employees must not:
•Jailbreak, root, or otherwise bypass the device's security controls.
•Store company files in personal cloud accounts or personal backup services.
•Forward company email to a personal email address.
•Share the device with family members or others while company data is accessible.
•Use unsecured public Wi-Fi for company work without [the company VPN].
Lost or stolen devices, and any suspected compromise, must be reported to
[IT / manager] within [24] hours or as soon as reasonably possible.
5. REIMBURSEMENT AND COST SHARING
[Choose the approach that fits your company and the states where your employees work.
Several states require reimbursement of necessary business expenses, and in those
states the required use of a personal phone for work generally triggers an obligation
to pay a reasonable share of the bill, even on an unlimited plan.]
[Option A: stipend] The company pays a monthly BYOD stipend of $______, added to the
employee's paycheck as [taxable / nontaxable reimbursement under an accountable plan],
intended to cover a reasonable portion of the service plan used for work.
[Option B: reimbursement] The company reimburses a reasonable percentage of the
employee's monthly service plan on submission of a bill and a completed expense form,
under the company's expense reimbursement policy.
[Option C: no personal device required] The company provides a company-owned device to
any employee whose role requires mobile access, and BYOD remains optional.
The company does not reimburse the purchase price of the device itself unless stated
in writing. Employees who believe the stipend does not cover their work use should
contact [HR] so the amount can be reviewed.
6. HOURS OF WORK AND NON-EXEMPT EMPLOYEES
This section applies to all non-exempt (overtime-eligible) employees.
•All time spent working counts as hours worked and must be recorded, including time
spent reading or answering work email, messages, or calls on a personal device
outside a scheduled shift.
•Non-exempt employees must not perform work on a personal device outside scheduled
hours without advance approval from their manager.
•Managers must not send messages that ask or imply a non-exempt employee should
respond outside scheduled hours.
•If a non-exempt employee does work outside scheduled hours, that time must be
recorded and will be paid, including overtime where applicable. Working unapproved
time may lead to corrective action, but it will always be paid.
7. REMOTE WIPE AND DATA REMOVAL
By enrolling a personal device, the employee agrees that [Company Name] may remove
company data from it. The company will use the narrowest method available:
•Selective wipe: removal of the company work profile, managed applications, and
company data only, leaving personal content in place. This is the default method.
•Full device wipe: a factory reset that erases everything on the device. This is used
only when a selective wipe is not technically possible and company or customer data
is at risk, for example on a device that is lost, stolen, or compromised.
The company may initiate a wipe when a device is reported lost or stolen, when a
security incident is suspected, when the employee leaves the company, or when access
is otherwise withdrawn.
The employee is solely responsible for backing up personal data. [Company Name] is not
responsible for the loss of personal photos, contacts, applications, purchases, or any
other personal content resulting from a wipe, or for any interruption to personal use
of the device.
8. PRIVACY AND MONITORING NOTICE
The company monitors company systems and company data, not the employee's personal
life. Monitoring is limited to company accounts, company applications, and the security
posture of the enrolled device. Some states require advance written notice of
electronic monitoring; this section serves as that notice, and the employee's signature
on the consent form records it. [Confirm your state's notice requirements.]
9. SEPARATION AND DEVICE RETURN
On the last day of employment, or earlier if access is withdrawn:
•Company accounts are disabled and company data is removed from the device following
the Device Return and Wipe Procedure.
•The employee must make the device available for removal of company data, or confirm
in writing that a remote removal succeeded.
•The employee must return any company-owned accessory, SIM, or peripheral.
•If the company's number is ported to the employee's device, or the employee's number
is used in company systems, the parties will address the number in writing before the
last day.
10. VIOLATIONS
Failure to follow this policy may result in loss of personal-device access and
corrective action up to and including termination of employment. Nothing in this policy
restricts an employee's right to discuss wages, hours, or working conditions, or to
engage in other legally protected activity.
ACKNOWLEDGMENT
I have received and read the [Company Name] BYOD Policy and agree to follow it as a
condition of using a personal device for work.
Employee signature: __ Date: _
DISCLAIMER: This is a sample template for general informational purposes only. It is
not legal advice and not a guarantee of compliance. Privacy, monitoring, wage-and-hour,
and expense-reimbursement laws vary by state and by the employee's work location and
change over time. Have this policy reviewed and adapted by qualified US employment
counsel before adopting it.
Template 2: Short BYOD Policy Statement
A one-page version for a small team or an employee handbook section. Seven numbered commitments, the non-exempt hours rule, the access boundary, and the stipend line, in a single signable statement. Grow into the full policy when regulated data enters the picture.
Short BYOD Policy Statement
BRING YOUR OWN DEVICE POLICY STATEMENT (SHORT)
[Company Name]
Effective date: _
A one-page version for a small team, or to drop into an employee handbook. Expand into
the full policy as the company grows or as regulated data enters the picture.
POLICY STATEMENT
Employees of [Company Name] may use a personal phone, tablet, or laptop to access
company email, files, and systems, with approval and after signing the BYOD consent
form. Using a personal device is voluntary; the company will provide a company-owned
device where a role requires mobile access.
Employees who use a personal device for work agree to:
1. Lock the device with a passcode or biometric and enable automatic screen lock.
2. Keep the operating system and applications updated, and never jailbreak or root the
device.
3. Use multi-factor authentication on every company account.
4. Keep company files inside company applications and never in personal cloud storage,
and never forward company email to a personal address.
5. Report a lost, stolen, or compromised device to [IT / manager] immediately.
6. Allow the company to remove company data from the device, including by remote wipe,
when the device is lost or compromised or when employment ends.
7. Back up their own personal data; the company is not responsible for personal content
lost during a wipe.
Non-exempt employees must record all time spent working on a personal device, including
email and messages outside a scheduled shift, and must get advance approval before
working outside scheduled hours.
The company accesses company accounts, company applications, and device security
settings only. It does not seek access to personal photos, personal messages, personal
accounts, or personal browsing.
[Company Name] [pays a monthly BYOD stipend of $______ / reimburses a reasonable
portion of the service plan] for employees required to use a personal phone for work.
ACKNOWLEDGMENT
I have received and read this BYOD Policy Statement and agree to follow it.
Employee signature: __ Date: _
DISCLAIMER: Sample template for general information only. Not legal advice. Have it
reviewed by qualified US employment counsel before adopting it.
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
The form that makes everything else defensible. Device details, policy acknowledgment, consent to device management, a separately initialed remote wipe consent, the non-exempt hours acknowledgment, and the reimbursement election. Collect it before access is granted, never after.
BYOD Consent and Acknowledgment Form
BYOD CONSENT AND ACKNOWLEDGMENT FORM
[Company Name]
Collect this signed form BEFORE granting a personal device access to company systems.
Keep it in the employee record. Re-collect it whenever the policy materially changes or
DISCLAIMER: Sample form for general information only. Not legal advice. Consent and
monitoring-notice requirements vary by state. Have this form reviewed by qualified US
employment counsel before using it.
Template 4: Device Return and Wipe Procedure
The internal runbook for removing company data: check for a legal hold first, cut access before wiping, choose the narrowest method, handle in-person removal, settle the phone number, and record what you did. Includes a section on what to do when a departing employee refuses.
Device Return and Wipe Procedure
DEVICE RETURN AND WIPE PROCEDURE
[Company Name]
For [IT / operations / the person handling offboarding]
This is the internal runbook for removing company data from a personal device. Use it at
termination, at resignation, when a device is lost or stolen, and when a device leaves
the BYOD program. Keep a completed copy in the employee record.
TRIGGER EVENTS
Run this procedure when any of the following happens:
•An employee resigns or is terminated (run it on or before the last day).
•A device is reported lost or stolen (run it immediately).
•A security incident or unauthorized access is suspected.
•An employee leaves the BYOD program or replaces the enrolled device.
•An employee stops meeting the security requirements in the BYOD Policy.
STEP 1: CONFIRM THE RECORD BEFORE YOU TOUCH THE DEVICE
[ ] Pull the employee's signed BYOD Consent and Acknowledgment Form.
[ ] Confirm Section 4 (remote wipe consent) is signed and initialed.
[ ] Confirm which device is enrolled (make, model, phone number).
[ ] Confirm there is no legal hold, litigation hold, or open investigation that
requires data on the device to be preserved. IF THERE IS A HOLD, STOP AND
CONTACT COUNSEL BEFORE WIPING ANYTHING.
Preservation beats speed. A wipe that destroys data subject to a hold is a much larger
problem than a few extra hours of access.
STEP 2: CUT ACCESS FIRST
Disabling accounts protects data even if the wipe fails or the device is offline.
[ ] Disable the company single sign-on account.
[ ] Revoke active sessions and refresh tokens on all company applications.
[ ] Reset or revoke application-specific passwords and API tokens.
[ ] Remove the account from the email and file-sharing tenants.
[ ] Remove the employee from shared drives, chat channels, and customer systems.
[ ] Rotate any shared credential the employee knew.
STEP 3: CHOOSE THE NARROWEST WIPE THAT WORKS
Selective wipe (DEFAULT): removes the company work profile, managed applications, and
company data, leaving personal content untouched. Use this whenever it is available.
[ ] Selective wipe issued from [MDM tool] on _____ at ___
[ ] Confirmation received from the tool: [ ] Yes [ ] Pending
Full device wipe (EXCEPTION ONLY): a factory reset that erases everything. Use only
when a selective wipe is not technically possible AND company or customer data is at
real risk, for example a lost or stolen device with no work-profile separation.
[ ] Full wipe authorized by: __ (name and title)
[ ] Reason a selective wipe was not possible: __
[ ] Employee notified before the full wipe: [ ] Yes [ ] Not possible, reason: _____
[ ] Full wipe issued on _____ at ___
STEP 4: IN-PERSON REMOVAL WHERE THE DEVICE IS AVAILABLE
For a planned exit, removing company data with the employee present is the lowest-risk
option and avoids most disputes.
[ ] Employee removes the work profile or company applications in front of [IT / HR].
[ ] Company email, file, and chat applications signed out and removed.
[ ] Company files in local storage or personal cloud folders located and deleted.
[ ] Saved company passwords removed from the device password manager or browser.
[ ] Company Wi-Fi profiles, VPN profiles, and certificates removed.
[ ] Device removed from the MDM inventory.
STEP 5: PHONE NUMBERS AND ACCESSORIES
[ ] Decide who keeps the phone number, and put the outcome in writing. If customers
call that number, address it before the last day.
[ ] Forward or reassign the work number if the company owns it.
[ ] Update the number in the CRM, phone tree, website, and email signature templates.
[ ] Collect any company-owned accessory, SIM, dongle, or security key.
[ ] Employee confirmation of removal received: [ ] Yes [ ] Not obtainable
[ ] Copy of this completed form filed in the employee record.
Employee acknowledgment (where available):
I confirm that company data and company applications have been removed from my personal
device, and that I retain no company files, credentials, or customer information.
Employee signature: __ Date: _
IF THE EMPLOYEE REFUSES
If a departing employee will not make the device available and will not confirm removal:
[ ] Confirm access has already been cut (Step 2).
[ ] Issue the selective wipe and document the attempt and the result.
[ ] Send a written request referencing the signed consent form and the policy.
[ ] Escalate to counsel before taking any further step. Do not attempt access outside
what the signed consent covers.
DISCLAIMER: Sample internal procedure for general information only. Not legal advice.
Wiping a personal device carries legal risk that varies by state and by the facts. Have
this procedure reviewed by qualified US employment counsel before using it.
Template 5: Mobile Device Security Standard
The technical companion listing the minimums you actually enforce: screen lock, auto-lock timeout, encryption, supported operating system, multi-factor authentication, data handling, network rules, and incident reporting windows, with a column for how each is enforced.
Mobile Device Security Standard
MOBILE DEVICE SECURITY STANDARD
[Company Name]
Companion to the BYOD Policy
Effective date: _ Owner: __
This standard states the minimum technical requirements for any personal device that
touches company data. Attach it to the BYOD Policy, or use it on its own if your policy
is short. Set the bracketed values to what your company can realistically enforce, then
enforce them.
1. MINIMUM DEVICE REQUIREMENTS
Requirement Minimum Enforced by
Screen lock Passcode, PIN of [6]+ MDM policy
digits, or biometric
Automatic lock timeout [5] minutes or less MDM policy
Device encryption Enabled MDM policy
Operating system A version still receiving MDM compliance rule
vendor security updates
Application updates Automatic updates on MDM policy
Jailbreak / root Not permitted MDM detection, blocks
access
Multi-factor authentication Required on all company Identity provider
accounts
Anti-malware (laptops) Required and current Endpoint agent
Backup of company data Company systems only, Policy
never personal cloud
Find-my-device / remote lock Enabled Policy
2. DATA HANDLING RULES
•Company files stay in company applications and company storage. Do not save company
documents to a personal cloud account, personal backup, or personal photo library.
•Do not forward company email to a personal email address.
•Do not paste customer data, credentials, or confidential information into personal
applications, personal notes, or third-party AI tools that are not company approved.
•Do not use SMS or personal messaging apps for [regulated data, for example health,
financial, or student records].
•Screenshots of company systems are treated as company data.
3. NETWORK RULES
•Use [the company VPN] on any network the employee does not control.
•Do not access company systems from a shared, public, or hotel computer.
•Keep the home router on a current firmware version with a non-default password.
4. APPLICATION AND SHARING RULES
•Install company applications only from the official application store or the company
catalog.
•Do not grant a third-party application access to a company account without approval
from [IT].
•Do not enable shared device profiles, guest profiles, or family sharing on a device
holding company data.
•Do not connect the device to a personal computer for backup while a company work
profile is present, unless [IT] approves.
5. INCIDENT REPORTING
Report the following to [IT / manager] within [24] hours or as soon as reasonably
possible:
•A lost or stolen device.
•A phishing message that was clicked, or credentials entered on a suspicious page.
•Unexpected application installs, unusual account activity, or a security warning.
•Any suspected exposure of customer or employee data.
Reporting quickly is never punished. Concealing an incident is a policy violation.
6. REVIEW
[IT / the policy owner] reviews this standard at least [annually] and after any material
change to the company's systems or applicable law.
DISCLAIMER: Sample technical standard for general information only. Not legal advice and
not a security certification. Adapt the settings to your systems and your risk, and have
regulated-industry requirements reviewed by qualified counsel.
Template 6: BYOD Stipend and Reimbursement Addendum
Four ways to pay for work use of a personal phone: a flat monthly stipend, a percentage of the actual bill, itemized reimbursement, or a company-owned device instead. Includes a state-specific section and a written process for an employee to request a review of the amount.
BYOD Stipend and Reimbursement Addendum
BYOD STIPEND AND REIMBURSEMENT ADDENDUM
[Company Name]
Companion to the BYOD Policy and the expense reimbursement policy
Effective date: _
Use this addendum to set out how the company pays for work use of a personal phone or
plan. Several states require reimbursement of necessary business expenses, and in those
states requiring an employee to use a personal phone for work generally creates an
obligation to pay a reasonable share of the bill, including where the employee is on an
unlimited plan. Confirm the rule for every state where an employee actually works.
1. WHO IS COVERED
This addendum applies to any employee who:
[ ] Is required to use a personal phone or personal device for work, OR
[ ] Is expected to be reachable on a personal device during scheduled hours, OR
[ ] Works in a state that requires reimbursement of necessary business expenses.
Employees who use a personal device purely by choice, where a company-owned device was
offered and declined, [are / are not] covered. [Confirm this treatment for your states.]
2. METHOD (CHOOSE ONE)
OPTION A: FLAT MONTHLY STIPEND
The company pays $___ per month per covered employee. The amount is intended to
cover a reasonable portion of the service plan attributable to work use. The stipend is
paid [with the regular paycheck / on the first paycheck of each month] and is treated as
[taxable wages / a nontaxable reimbursement under an accountable plan; confirm treatment
with your tax advisor].
Standard roles: $___ per month
Heavy-use roles (field, on-call, customer-facing): $___ per month
Data-only or tablet use: $___ per month
OPTION B: PERCENTAGE OF THE ACTUAL BILL
The company reimburses ___% of the employee's monthly service plan on submission
of a bill showing the plan cost. The employee may redact personal call and message
detail before submitting. Submit within [30] calendar days of the billing date.
OPTION C: ITEMIZED REIMBURSEMENT
The company reimburses documented, work-attributable charges (for example international
roaming for a business trip, or an added data package for a work project) through the
normal expense process, with a receipt and a business purpose.
OPTION D: COMPANY-PROVIDED DEVICE
The company issues a company-owned phone and plan. No stipend applies. This is the
cleanest option where reimbursement rules are strict or the data is sensitive.
3. WHAT IS AND IS NOT COVERED
Covered:
•A reasonable portion of the monthly voice and data plan for required work use.
•Work-required international roaming or data add-ons, with prior approval.
•[Optional: a share of home internet where remote work requires it.]
Not covered unless approved in writing:
•The purchase price of the device or a device upgrade.
•Device insurance, accessories, cases, or chargers.
•Repairs, replacements, or out-of-warranty service.
•Personal applications, personal subscriptions, or personal content.
4. HOW TO REQUEST A REVIEW
An employee who believes the stipend does not reasonably cover required work use may
submit a written request to [HR] with a short explanation and, if available, a copy of
the bill. The company will review the request within [15] business days and will adjust
the amount where the request is reasonable. Employees are not discouraged from raising
this, and no employee will face retaliation for asking.
5. STATE-SPECIFIC TERMS
[List the states where your employees work and the treatment that applies in each, for
example: employees working in a necessary-expense state receive Option B at a percentage
set with counsel; employees in other states receive Option A.]
State: Method: Amount:
State: Method: Amount:
State: Method: Amount:
6. CHANGES
The company may change stipend amounts or methods prospectively with [30] days written
notice, subject to applicable law.
ACKNOWLEDGMENT
I have received and read this BYOD Stipend and Reimbursement Addendum and understand how
work use of my personal device will be paid.
Employee signature: __ Date: _
DISCLAIMER: Sample template for general information only. Not legal advice and not tax
advice. Expense-reimbursement obligations and the tax treatment of stipends vary by
state and by facts. Have this addendum reviewed by qualified US employment counsel and
your tax advisor before adopting it.
What Happens at Termination
At separation, cut access first and wipe second. Disabling the account and revoking active sessions protects company data even if the device is offline, the employee refuses to hand it over, or the wipe command never lands. Reversing that order is how companies end up with a wiped phone and a still-valid session.
Before anything else, check for a legal hold. If there is litigation, an investigation, or a preservation obligation touching that employee, a wipe destroys evidence and turns a manageable problem into a serious one. Stop and call counsel. Preservation always beats speed, and this is the one step in the procedure with no acceptable shortcut.
1
Confirm the signed consent and check for a hold
Pull the signed consent form, confirm the wipe section was initialed, identify the enrolled device, and verify no legal hold applies. If a hold exists, stop and contact counsel before touching the device.
2
Cut access before you touch the device
Disable single sign-on, revoke active sessions and refresh tokens, remove the account from email and file sharing, and rotate any shared credential the person knew.
3
Run a selective wipe where you can
Remove the work profile, managed applications, and company files. Reserve a full factory reset for a lost, stolen, or compromised device where separation is not technically possible, with a named authorizer and a written reason.
4
Do the removal in person for a planned exit
Where the exit is planned and the person is cooperative, removing company applications together is the lowest-risk option: it avoids disputes and lets you catch saved passwords, VPN profiles, and local files.
5
Settle the phone number and accessories
Decide in writing who keeps the number, port or forward a company-owned line, update the CRM, website, and signatures, and collect any company SIM, dongle, or security key.
6
Record the outcome in the employee file
Log the method, date, time, who performed it, and any employee confirmation, and file the completed procedure. A record you can produce is the point of the whole exercise.
Fold these steps into your broader exit routine rather than running them separately, because the device is only one of the systems that needs to close on the last day. Our IT offboarding checklist covers the accounts and access side, and the wipe procedure above is the personal-device half of the same job.
BYOD at a Small Business
A large company runs BYOD through a security team, a mobile device management platform, and a legal department that reviews the consent language. A small business runs it through whoever answers the question first, usually after someone has already added the company email account to a phone nobody approved. Here is what matters most at that scale.
BYOD is already happening at your company, whether or not you approved it
Almost every small business is running BYOD by default. Someone added the company email account to their phone during their first week, someone else has customer numbers saved in their personal contacts, and a manager runs the team chat from a phone the company has never seen. Nobody made a decision; it simply accumulated. The practical question is therefore not whether to allow personal devices, it is whether the arrangement is written down and signed before the day you need it. The day you need it is always a bad day: a phone left in a rideshare, a resignation that turns hostile, a customer list that walked out the door. A policy signed on day one costs an hour. The same conversation held after an incident costs a great deal more.
The wipe is the part that turns into a lawsuit, and consent is the part that prevents it
Wiping a departing employee's personal phone without written consent is the single most common way a small company turns a routine exit into a legal problem. The federal claims are not always the danger. In one Texas case a court threw out an ex-employee's federal claims after his personal phone was remotely wiped: the Stored Communications Act claim failed because data sitting on a personal device is not in electronic storage as that statute uses the term, and the computer-fraud claim failed on a separate ground, that the loss he claimed did not meet the statutory threshold (Rajaee v. Design Tech Homes, S.D. Tex., 2014). What that case actually shows is how much litigation an unsigned consent buys you, and his state conversion, theft, and negligence claims were dismissed without prejudice, meaning they were left open rather than decided. Two things make the difference: a signed consent that separately initials the wipe language, and a technical setup where a selective wipe removes only company data. Get both and the wipe becomes an administrative step instead of a dispute.
A policy nobody signed, and nobody can find, is not a policy
The BYOD policy is worth exactly as much as your ability to produce a signed copy with a date on it. That is a document problem before it is a security problem, and it is the part small teams get wrong: the file sits in a shared drive, half the team never opened it, and the one person who could confirm who signed what has left. This is the people side FirstHR is built for. E-signature captures the consent form before access is granted, document management stores the signed version with the device details on record, employee profiles keep the enrolled device and the reimbursement election next to the rest of the employment file, the self-service portal lets employees pull up the current policy without asking, and task workflows can route enrollment through manager and IT approval, then run the removal checklist at offboarding. To be clear about scope, FirstHR is an onboarding and HR platform, not a law firm and not a device management tool, so pair it with your IT stack and your counsel. Applicant tracking is coming soon to FirstHR. The templates below work on their own; FirstHR is how you sign, store, and prove them.
Sign, Store, and Enforce
A BYOD policy is worth what you can prove. That means adapting the right version, collecting a signed consent before access is granted, enforcing the security minimums through a tool rather than trust, and running the removal procedure the same way every time someone leaves.
Adapt the policy
Pick the full policy or the short statement, set your passcode, timeout, and reporting values, choose a reimbursement method for each state where people work, and have US counsel review.
Sign before access
Send the consent form and collect a signature with the wipe section initialed. Grant company access only after it is signed, never before.
Enforce the minimums
Apply the security standard through your device management tool so the requirements are checked automatically rather than trusted, and keep a device inventory.
Run the exit procedure
At offboarding, check for a legal hold, cut access, run the narrowest wipe, settle the phone number, and file the completed procedure in the employee record.
The templates above work on their own. To sign and store them without paper, FirstHR captures the consent form with built-in e-signature, keeps the signed version and the device details in the employee record through document management, and gives people self-service access to the current policy. Task workflows can route enrollment through manager and IT approval, then trigger the removal checklist at offboarding. Applicant tracking is coming soon to FirstHR.
To be clear about scope, FirstHR is an onboarding and HR platform, not a law firm, not a payroll provider, and not a device management tool. It handles the people and document side: signature, storage, profiles, and workflow. Pair it with your IT stack for the technical enforcement and with US employment counsel for the legal review, and pair this policy with your broader remote work policy if people work outside the office. Applicant tracking is coming soon to FirstHR.
Key Takeaways
A BYOD policy sets the terms for personal-device access to company systems, it works only alongside a signed consent form and an internal removal procedure, and it should state what the company will not access, not just what it can.
Remote wipe requires written consent obtained before access, with the wipe language initialed separately, and a selective wipe should always be the default over a full factory reset.
Several states require reimbursing necessary business expenses, and California requires a reasonable percentage of the phone bill even on an unlimited plan; the FLSA free and clear rule sets a floor everywhere.
After-hours email on a personal phone is hours worked for non-exempt employees whenever the employer knows or has reason to believe the work is happening, so it must be recorded and paid.
At termination, check for a legal hold, cut access before wiping, run the narrowest removal method, settle the phone number, and file a record of what was done.
These templates are US-first starting points, not certified compliance; have US counsel review. This is general information, not legal advice.
Frequently Asked Questions
What is a BYOD policy?
A BYOD policy, short for bring your own device, is a written agreement that sets the terms under which employees may use a personal phone, tablet, or laptop to access company email, files, and systems. It covers who is eligible, how a device is enrolled, the security settings the company requires, what the company can and cannot access on the device, how work use of the phone plan is paid for, how hours are recorded for overtime-eligible employees, and what happens to company data when someone leaves. The policy is only half the document set. The other half is a signed consent form, collected before access is granted, that records the employee’s agreement to device management and to removal of company data. This is general information, not legal advice.
Can an employer remotely wipe an employee’s personal phone?
In practice yes, but only with written consent, and the safer approach is to remove company data only. A selective wipe deletes the company work profile, managed applications, and company files while leaving personal photos, contacts, and messages untouched, and that should be the default. A full factory reset erases everything and should be reserved for a lost, stolen, or compromised device where a selective wipe is not technically possible. What makes either defensible is a consent form the employee signed before access was granted, ideally with the wipe language initialed separately so there is no argument about notice. Wiping a personal device without that consent is the most common way a routine exit becomes a legal dispute, and state property and privacy claims are separate from any federal analysis. This is general information, not legal advice.
Do employers have to pay for an employee’s personal phone under a BYOD policy?
It depends on the state. There is no general federal statute requiring reimbursement of a personal phone bill, but several states require employers to reimburse necessary business expenses, and requiring work use of a personal phone falls inside that in those states. California Labor Code section 2802 requires indemnifying employees for all necessary expenditures incurred in direct consequence of their duties, and a California appellate decision held that this means reimbursing a reasonable percentage of the phone bill even when the employee is on an unlimited plan and even when someone else pays the bill. Illinois has a similar necessary-expense provision in its wage act. Federal law adds a floor everywhere: an expense that primarily benefits the employer cannot cut a non-exempt employee’s pay below minimum wage or reduce overtime. Confirm the rule for each state where someone actually works. This is general information, not legal advice.
Does answering work email on a personal phone count as hours worked?
Yes, for non-exempt employees. Under the Fair Labor Standards Act, work that is suffered or permitted counts as hours worked, and the Department of Labor hours-worked regulations at 29 CFR 785.11 and 785.12 extend that to work done away from the workplace: if the employer knows or has reason to believe the work is being performed, it must count the time as hours worked. A non-exempt employee reading and answering work messages on a personal phone after a shift is working, and that time must be recorded and paid, including overtime if it pushes the week over the threshold. The practical controls are a policy that requires advance approval before working outside scheduled hours, a rule that unrecorded time gets reported and paid anyway, and manager training so nobody sends after-hours messages that imply an immediate reply. Discipline for unapproved time is allowed; refusing to pay it is not. This is general information, not legal advice.
What should a BYOD policy include?
A complete BYOD policy includes eligibility and an enrollment process, a clear statement of what the company can access and what it will not touch, minimum security requirements such as a passcode, auto-lock timeout, encryption, a supported operating system version, and multi-factor authentication, rules on where company data may be stored, a reimbursement or stipend method, an hours-of-work section for overtime-eligible employees, remote wipe terms distinguishing a selective wipe from a full reset, a monitoring notice where the state requires one, and a separation section covering device return and the phone number. It should also state that participation is voluntary and that a company-owned device is available for roles that need one. The policy pairs with a signed consent form and an internal removal procedure; without those two, the policy alone does very little. This is general information, not legal advice.
What is the difference between a BYOD policy and a cell phone policy?
A cell phone policy is mostly about conduct: when phones may be used during work, driving rules, camera restrictions, and personal calls on the floor. A BYOD policy is about access and data: the terms under which a personal device is allowed to hold company email, files, and customer information, and what happens to that data afterward. They overlap, and a small company can reasonably combine them, but the BYOD half carries the parts with legal weight: consent to device management, remote wipe, reimbursement, and hours of work. If you already have a cell phone policy that only covers usage during shifts, treat the templates on this page as the missing half rather than a replacement. Adopt both, or fold the BYOD sections into the existing document. This is general information, not legal advice.
Should a small business allow BYOD at all?
For most small businesses the honest answer is that BYOD is already happening, so the real choice is between an unwritten arrangement and a documented one. Personal devices save money and people prefer carrying one phone, which is why the practice spreads without anyone approving it. The cases where a company-owned device is worth the cost are narrow but real: regulated data such as health or financial records, roles with heavy customer contact where the phone number matters commercially, and any situation where a full wipe would be the only removal option. A reasonable middle path is BYOD by default with a signed consent form and enforced security minimums, plus company-owned devices for the handful of roles where the risk justifies it. Make participation genuinely voluntary and offer an alternative. This is general information, not legal advice.
Who owns the phone number when an employee leaves?
Whoever holds the account with the carrier, which is why this needs to be settled in writing before the last day rather than argued afterward. If the employee has always paid the carrier and simply used the number for work, the number is theirs, and the company’s exposure is that customers keep calling a former employee. If the company owns the line and ported it to the employee’s device, the company should port it back or forward it before access ends. The messy middle case is a personal number that customers now treat as the company’s number, and the practical fixes are to publish a main company line rather than individual mobiles, to route customer contact through company systems, and to add a short paragraph to the BYOD policy stating how the number is handled at separation. Update the CRM, website, and signatures the same week. This is general information, not legal advice.